You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GCP Cloud Run中API与view服务间Nginx连接失败求助

问题:Cloud Run中Nginx无法解析API服务地址导致启动失败

环境与现状

  • 两个GCP Cloud Run服务:API(正常启动,可正常访问端点)和view(启动失败)
  • 初始状态均未使用VPC,对外开放
  • API启动日志:
Default STARTUP TCP probe succeeded after 1 attempt for container "api-1" on port 8080.

错误现象

view服务启动失败,Nginx抛出域名解析错误:

2023/06/02 05:14:11 [emerg] 1#1: host not found in upstream "api:8080" in /etc/nginx/nginx.conf:44

nginx: [emerg] host not found in upstream "api:8080" in /etc/nginx/nginx.conf:44

尝试使用API的主机URL、api-1、api作为目标地址后,问题依旧,最新报错:

2023/06/04 09:51:50 [emerg] 1#1: host not found in upstream "api:8080" in /etc/nginx/nginx.conf:44

相关配置文件

原始Nginx配置

daemon off;
user nginx;

events {
    worker_connections 1024;
}

http {
    gzip on;
    gzip_comp_level 2;
    gzip_min_length 1024;
    gzip_types *;

    proxy_connect_timeout       300;
    proxy_send_timeout          300;
    proxy_read_timeout          300;
    send_timeout                300;
    keepalive_timeout 300;
    client_body_timeout 300;
    client_header_timeout 300;
    client_max_body_size 1024M;
    proxy_max_temp_file_size 0;
    proxy_buffering off;
    server_names_hash_bucket_size 256;

    include /etc/nginx/mime.types;
    sendfile on;
    server_tokens off;

    log_format  main '$remote_addr - $remote_user [$time_local] "$request" '
                     '$status $body_bytes_sent "$http_referer" '
                     '"$http_user_agent" "$http_x_forwarded_for"';

    access_log  /var/log/nginx/access.log  main;

    default_type application/octet-stream;

    map $http_upgrade $connection_upgrade {
        default upgrade;
        ''      close;
    }

     upstream api {
        server ${API_HOST}:${API_PORT};
     }

     # ssl_session_cache   shared:SSL:10m;
     # ssl_session_timeout 10m;

     server {
         listen 8080;

         # SSL configuration
         listen 443 ssl;
         listen [::]:443 ssl;

         server_name localhost;

         keepalive_timeout   70;

         root /usr/share/nginx/html;

         access_log /var/log/nginx/access.log;
         error_log /var/log/nginx/error.log;

         location ~* \.(js|css|png|jpg|jpeg|gif|svg|ico|woff|woff2|ttf)$ {
             expires 1y;
             add_header Cache-Control "public";
             access_log off;
         }

         location / {
            try_files $uri /index.html;
         }

         location ~ ^/(v1)/ {
             proxy_set_header X-Real-IP $remote_addr;
             proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
             proxy_set_header X-Forwarded-Proto $scheme;
             proxy_set_header Host $http_host;
             proxy_set_header X-NginX-Proxy true;

             proxy_http_version 1.1;
             proxy_set_header Upgrade $http_upgrade;
             proxy_set_header Connection $connection_upgrade;

             proxy_redirect off;
             proxy_pass http://api;

             add_header Cache-Control "no-store, no-cache, must-revalidate";
             expires off;
         }

     }

}

更新后的Nginx配置片段

server {
     listen ${PORT};

     # SSL configuration
     listen 443 ssl;
     listen [::]:443 ssl;

Nginx启动脚本start.sh

#!/usr/bin/env sh
set -eu

# Replace env vars in config template and save it as config file
envsubst '${API_HOST}','${API_PORT}','${PORT}'  < /etc/nginx/etc/nginx/nginx.conf.template > /etc/nginx/nginx.conf
# Run nginx
exec /usr/sbin/nginx

已尝试的操作

  1. 调整Nginx配置,引入环境变量替换监听端口
  2. 创建带有Cloud Run Invoker和Cloud Run Admin权限的自定义服务账号,分配给两个服务
  3. 创建VPC并关联两个服务
  4. 修改Nginx配置,添加server_name localhost ${API_HOST};并额外监听80端口

解决建议

  • 验证环境变量替换有效性:在start.sh中添加调试步骤,比如替换完成后打印/etc/nginx/nginx.conf内容,或启动时执行echo ${API_HOST}确认变量是否正确传入。注意envsubst语法,当前逗号分隔写法可能存在问题,可改为envsubst '$API_HOST $API_PORT $PORT'尝试。
  • 使用API服务完整域名:Cloud Run服务对外访问域名为https://<service-name>-<hash>-<region>.a.run.app,将API_HOST设为该完整域名,API_PORT设为443,同时修改Nginx的proxy_pass为https://api,并添加proxy_ssl_server_name on;等SSL适配配置(Cloud Run默认走HTTPS)。
  • 优化Nginx DNS解析逻辑:Nginx默认启动时解析上游地址,失败则启动失败。可添加DNS resolver配置,让请求时才解析地址:
    resolver 8.8.8.8 valid=300s;
    resolver_timeout 5s;
    
    location ~ ^/(v1)/ {
        # ...其他配置
        proxy_pass https://$API_HOST:$API_PORT;
    }
    
    也可直接去掉upstream块,在proxy_pass中使用变量。
  • 检查VPC与权限配置:若使用VPC,确保两个服务连接同一VPC并配置Serverless VPC Access连接器,同时确认API服务的ingress设置允许VPC内流量访问;检查view服务的服务账号是否在API服务的IAM权限列表中,确保拥有调用权限。

内容的提问来源于stack exchange,提问作者Mike3355

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.20 03:05:22